Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
478cf312 by Salvatore Bonaccorso at 2026-08-27T22:31:02+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37,127 +37,127 @@ CVE-2026-81722 (nltk PorterStemmer in versions <= 3.10.2
(fixed in 3.10.3) conta
- nltk 3.10.3-1
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-ww6m-cw3f-q94g
CVE-2026-81721 (openssl_encrypt before 1.4.9 fails to validate KDF cost
parameters in ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81720 (openssl_encrypt before 1.4.9 fails to validate the memory_cost
paramet ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81719 (openssl_encrypt before 1.4.9 executes untrusted third-party
plugins wi ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81718 (openssl_encrypt versions before 1.4.9 use under-parameterized
PBKDF2-H ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81717 (openssl_encrypt (pip package openssl-encrypt) before 1.4.9
contains tw ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81716 (openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9
contain a ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81715 (openssl_encrypt (pip package openssl-encrypt) versions <=
1.4.8 do not ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81714 (openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use
suffix-to ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81707 (openssl_encrypt before 1.4.9 fails to sanitize the email field
of impo ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81706 (openssl_encrypt before 1.4.9 fails to prevent namespace
collisions bet ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81705 (openssl-encrypt before 1.4.9 fails to redact the file password
in its ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81704 (openssl_encrypt versions before 1.4.9 contain a weak key
derivation vu ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81703 (openssl_encrypt versions before 1.4.9 fail to validate
encryption stat ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81702 (openssl_encrypt before 1.4.9 fails to re-derive and validate
fingerpri ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81701 (openssl_encrypt versions before 1.4.9 use a denylist to
identify trust ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81700 (openssl_encrypt versions before 1.4.9 contain a signature
verification ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81699 (openssl_encrypt versions before 1.4.9 fail to properly
validate key de ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81698 (openssl_encrypt versions before 1.4.9 contain a shell
injection vulner ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81697 (openssl_encrypt (pip package openssl-encrypt) versions <=
1.4.8 contai ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81696 (openssl_encrypt versions before 1.4.9 fail to sanitize
terminal contro ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81695 (openssl_encrypt versions before 1.4.9 fail to escape
attacker-controll ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81694 (openssl-encrypt (pip package, versions <= 1.4.8) fails to
sanitize fil ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81693 (openssl_encrypt before 1.4.9 fails to validate the total field
from QR ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81692 (openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and
earlier fail ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81691 (openssl_encrypt versions before 1.4.9 fail to validate server
URLs in ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81690 (openssl-encrypt (pip package) before 1.4.9 contains a
symlink-followin ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81689 (openssl_encrypt versions before 1.4.9 derive the remote-pepper
wrap ke ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81688 (openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256
hash of ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81687 (openssl_encrypt versions before 1.4.9 fail to enforce a time
ceiling o ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81686 (openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus
crypto s ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81685 (openssl_encrypt versions before 1.4.9 fail to sanitize
recovery-slot m ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81684 (In openssl_encrypt (pip package openssl-encrypt) versions <=
1.4.8, th ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81683 (openssl_encrypt (pip package openssl-encrypt) versions 1.4.8
and earli ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81682 (openssl_encrypt versions before 1.4.9 contain an insecure file
permiss ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81681 (openssl_encrypt (pip package openssl-encrypt) versions <=
1.4.8 advert ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81680 (openssl_encrypt versions before 1.4.9 fail to authenticate
recovery-sl ...)
- TODO: check
+ NOT-FOR-US: OpenSSL Encrypt
CVE-2026-81679 (OpenRemote versions before 1.28.0 contain a cross-realm
information di ...)
- TODO: check
+ NOT-FOR-US: OpenRemote
CVE-2026-81678 (AVideo before 24.0 contains a server-side request forgery
vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: WWBN AVideo
CVE-2026-81677 (The \u2018/ws/apiprensa/getVideo\u2019 endpoint is vulnerable
to SQL i ...)
- TODO: check
+ NOT-FOR-US: TOOOLS iSquad
CVE-2026-81676 (A vulnerability in the endpoint
\u2018/ws/apitribuna/ultimosVideos\u20 ...)
- TODO: check
+ NOT-FOR-US: TOOOLS iSquad
CVE-2026-81675 (The endpoint \u2018/ws/apiprensa/getVideoUltimasSeccion\u2019
contains ...)
- TODO: check
+ NOT-FOR-US: TOOOLS iSquad
CVE-2026-81674 (The endpoint \u2018/ws/apiprensa/getVideoNextPrev\u2019 is
vulnerable ...)
- TODO: check
+ NOT-FOR-US: TOOOLS iSquad
CVE-2026-81673 (The \u2018/ws/apitribuna/setVisita\u2019 endpoint is
vulnerable to SQL ...)
- TODO: check
+ NOT-FOR-US: TOOOLS iSquad
CVE-2026-81672 (SQL injection vulnerability in the
\u2018/ws/apiprensa/getVideoSubcana ...)
- TODO: check
+ NOT-FOR-US: TOOOLS iSquad
CVE-2026-81668 (A flaw was found in Katello where the Content View Filter
Rules API do ...)
- TODO: check
+ NOT-FOR-US: Katello
CVE-2026-81664 (The OpenFaaS gateway registers GET /system/telemetry in
gateway/main.g ...)
- TODO: check
+ NOT-FOR-US: OpenFaaS gateway
CVE-2026-81662 (Affected versions of Flowintel improperly trust configuration
keys sup ...)
- TODO: check
+ NOT-FOR-US: Flowintel
CVE-2026-81659 (Affected versions of Flowintel allow attacker-controlled note
content ...)
- TODO: check
+ NOT-FOR-US: Flowintel
CVE-2026-81658 (A flaw was found in Foreman. The template revision endpoint
does not e ...)
TODO: check
CVE-2026-81625 (A remote attacker with user privileges may use a malicious or
compromi ...)
- TODO: check
+ NOT-FOR-US: Greenbone
CVE-2026-81581 (Improper validation of memory boundaries in WibuKey64.sys of
WibuKey u ...)
- TODO: check
+ NOT-FOR-US: WibuKey
CVE-2026-81579 (In WibuKey for Windows before version 6.71, an untrusted
pointer deref ...)
- TODO: check
+ NOT-FOR-US: WibuKey
CVE-2026-81576 (If configured as a server, CodeMeter Runtime before versions
8.41a and ...)
- TODO: check
+ NOT-FOR-US: CodeMeter Runtime
CVE-2026-81575 (If configured as a server, CodeMeter Runtime before versions
8.41a and ...)
- TODO: check
+ NOT-FOR-US: CodeMeter Runtime
CVE-2026-81574 (In CodeMeter Runtime before versions 8.41a and 9.10, the
logger does n ...)
- TODO: check
+ NOT-FOR-US: CodeMeter Runtime
CVE-2026-81573 (If CodeMeter Runtime before 8.41a or 9.10 is configured as a
server, t ...)
- TODO: check
+ NOT-FOR-US: CodeMeter Runtime
CVE-2026-81572 (cmu.exe --create-io --file C: creates a predictable temporary
file und ...)
- TODO: check
+ NOT-FOR-US: Wibu
CVE-2026-81562 (A security flaw has been discovered in AlexGladkov
claude-in-mobile 3. ...)
- TODO: check
+ NOT-FOR-US: AlexGladkov claude-in-mobile
CVE-2026-81560 (A vulnerability was identified in blackms aistack up to 1.6.1.
Affecte ...)
- TODO: check
+ NOT-FOR-US: blackms aistack
CVE-2026-81335 (Baserow dispatches an Application Builder data source without
acting o ...)
- TODO: check
+ NOT-FOR-US: Baserow
CVE-2026-81334 (darknet subscripts its layer array with an index taken from a
configur ...)
- TODO: check
+ NOT-FOR-US: darknet
CVE-2026-81279 (Subscriber Broken Access Control in Push Notification for Post
and Bud ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81277 (Contributor SQL Injection in Suggestion Engine for WooCommerce
<= 2.0. ...)
@@ -173,15 +173,15 @@ CVE-2026-81272 (Editor Broken Access Control in
FluentPlayer Pro <= 1.3.2 versio
CVE-2026-81271 (Unauthenticated Cross Site Request Forgery (CSRF) in
GeoDirectory <= 2 ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-81102 (The Dash MCP server bound its listener to the loopback address
but nev ...)
- TODO: check
+ NOT-FOR-US: Dash MCP server
CVE-2026-81101 (The configure command accepted any endpoint URL and stored it
beside t ...)
- TODO: check
+ NOT-FOR-US: Airtable
CVE-2026-81100 (tiger-gh-mcp-server started its MCP HTTP transport without
enabling th ...)
- TODO: check
+ NOT-FOR-US: tiger-gh-mcp-server
CVE-2026-81099 (tiger-slack started its MCP HTTP transport without enabling
the host a ...)
- TODO: check
+ NOT-FOR-US: tiger-slack
CVE-2026-81098 (The Telnyx MCP server exposed its HTTP transport on every
interface an ...)
- TODO: check
+ NOT-FOR-US: Telnyx MCP server
CVE-2026-81097 (The execute_ruby tool is documented as a read-only Ruby
sandbox and is ...)
TODO: check
CVE-2026-81096 (ToolUniverse ran caller-supplied Python inside a sandbox that
could be ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/478cf312f038366a565ae4d04fb6ff542a5ad5b6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/478cf312f038366a565ae4d04fb6ff542a5ad5b6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits